Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 331

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
S&P 500 closes higher Friday as Amazon surges; Dow posts fourth straight winning month: Live updates
450,000 defrauded student loan borrowers are eligible for debt forgiveness — here's who qualifies
August kicks off next week with jobs report, earnings as momentum recovers. Here's what's ahead
Trump appeals order that slammed his IRS lawsuit and referred his lawyer to bar
Special Event: Rifftrax Shorts: Educational Credit
Star Trek: Strange New Worlds: The Griffin Incident
Movie: Horatio's Drive: America's First Road Trip
To keep growing, incoming Best Buy CEO says he first wants to go smaller
Looking at just the odds isn’t enough. How traders gain an edge on prediction markets
EV prices aren't following the 'law of used cars,' analyst says — what it means for buyers and sellers